PT-2026-73052 · Siyuan · Siyuan

·

CVE-2026-73045

·

Published

2026-08-15

·

Updated

2026-08-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description An improper restriction of excessive authentication attempts exists in the 'authFilePublishAccess' endpoint. This allows unauthenticated attackers to perform brute-force attacks against per-notebook publish passwords by submitting unbounded guesses, as the system lacks rate limiting or CAPTCHA mechanisms. Successful exploitation grants unauthorized access to password-protected published notebooks.
Recommendations Update SiYuan to version 3.7.4 or later. As a temporary mitigation, restrict access to the 'authFilePublishAccess' endpoint to minimize the risk of brute-force attacks.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73045

Affected Products

Siyuan